Privacy Policy

Last updated: March 2026

Analytics

Super Search Console uses PostHog for product analytics to understand how the app is used. Analytics events are always routed through our own servers — never directly to PostHog's infrastructure.

Before you give consent, PostHog runs in memory-only mode: events are sent anonymously without writing any cookies or data to your browser's local storage. Your identity is not persisted across sessions.

If you accept analytics via the banner, PostHog switches to persistent mode which stores a distinct ID in a cookie and local storage so your usage can be tracked across sessions. If you decline, the anonymous memory-only mode continues and no persistent data is stored.

How it works

When you sign in with Google or Microsoft, your OAuth tokens are stored in an encrypted, HTTP-only session cookie. The cookie is encrypted with a key held only by Super Search Console's servers — neither you nor any third party can read its contents directly.

All API calls to Google Search Console, Google Indexing API, and Bing Webmaster Tools are made server-side: your browser sends requests to our servers, which fetch data from Google and Microsoft on your behalf and forward the results back to you. No API response data is stored on our servers.

Cookies

Two types of cookies may be set:

  • Session cookie — an encrypted HTTP-only cookie that holds your OAuth tokens. It exists solely to keep you logged in and can only be decrypted by our servers.
  • Analytics consent cookie (analytics-consent) — stores your Consent Mode v2 preferences (granular consent fields, including analytics_storage) for one year so the banner doesn't re-appear.
  • PostHog identity cookie — set only if you accept analytics. Stores a random distinct ID and session ID so your usage can be tracked across visits.

Third-party services

Authenticating via Google or Microsoft means you are subject to their respective privacy policies. Super Search Console itself does not share any data with any third parties beyond the API calls you explicitly initiate.

v0.2.0

We use anonymous analytics to understand how the app is used. Learn more